1
0
mirror of synced 2026-08-05 17:57:15 +00:00

SEC-2015: Add spring-security-test

This commit is contained in:
Rob Winch
2014-04-22 16:47:48 -05:00
parent 1c75d33adb
commit 8baf82532c
48 changed files with 4647 additions and 10 deletions
+2
View File
@@ -22,4 +22,6 @@ dependencies {
runtime "opensymphony:sitemesh:2.4.2",
'cglib:cglib-nodep:2.2.2',
'ch.qos.logback:logback-classic:0.9.30'
testCompile project(":spring-security-test")
}
+6
View File
@@ -208,6 +208,12 @@
<version>1.9.5</version>
<scope>test</scope>
</dependency>
<dependency>
<groupId>org.springframework.security</groupId>
<artifactId>spring-security-test</artifactId>
<version>4.0.0.CI-SNAPSHOT</version>
<scope>test</scope>
</dependency>
<dependency>
<groupId>org.springframework</groupId>
<artifactId>spring-test</artifactId>
@@ -1,5 +1,5 @@
/*
* Copyright 2002-2013 the original author or authors.
* Copyright 2002-2014 the original author or authors.
*
* Licensed under the Apache License, Version 2.0 (the "License");
* you may not use this file except in compliance with the License.
@@ -15,19 +15,126 @@
*/
package org.springframework.security.samples.config;
import static org.springframework.security.test.web.servlet.request.SecurityMockMvcRequestBuilders.*;
import static org.springframework.security.test.web.servlet.request.SecurityMockMvcRequestPostProcessors.*;
import static org.springframework.security.test.web.servlet.response.SecurityMockMvcResultMatchers.*;
import static org.springframework.test.web.servlet.request.MockMvcRequestBuilders.*;
import static org.springframework.test.web.servlet.result.MockMvcResultMatchers.*;
import javax.servlet.Filter;
import org.junit.Before;
import org.junit.Test;
import org.junit.runner.RunWith;
import org.springframework.beans.factory.annotation.Autowired;
import org.springframework.security.samples.mvc.config.WebMvcConfiguration;
import org.springframework.security.test.context.support.WithMockUser;
import org.springframework.security.test.context.support.WithSecurityContextTestExcecutionListener;
import org.springframework.test.context.ContextConfiguration;
import org.springframework.test.context.TestExecutionListeners;
import org.springframework.test.context.junit4.SpringJUnit4ClassRunner;
import org.springframework.test.context.support.DependencyInjectionTestExecutionListener;
import org.springframework.test.context.support.DirtiesContextTestExecutionListener;
import org.springframework.test.context.transaction.TransactionalTestExecutionListener;
import org.springframework.test.context.web.ServletTestExecutionListener;
import org.springframework.test.context.web.WebAppConfiguration;
import org.springframework.test.web.servlet.MockMvc;
import org.springframework.test.web.servlet.request.MockHttpServletRequestBuilder;
import org.springframework.test.web.servlet.setup.MockMvcBuilders;
import org.springframework.web.context.WebApplicationContext;
/**
* @author Rob Winch
*
*/
@RunWith(SpringJUnit4ClassRunner.class)
@ContextConfiguration(classes=SecurityConfig.class)
@ContextConfiguration(classes={RootConfiguration.class, WebMvcConfiguration.class})
@WebAppConfiguration
@TestExecutionListeners(listeners={ServletTestExecutionListener.class,
DependencyInjectionTestExecutionListener.class,
DirtiesContextTestExecutionListener.class,
TransactionalTestExecutionListener.class,
WithSecurityContextTestExcecutionListener.class})
public class SecurityConfigTests {
private MockMvc mvc;
@Autowired
private WebApplicationContext context;
@Autowired
private Filter springSecurityFilterChain;
@Before
public void setup() {
mvc = MockMvcBuilders
.webAppContextSetup(context)
.addFilters(springSecurityFilterChain)
.defaultRequest(get("/").with(testSecurityContext()))
.build();
}
@Test
public void securityConfigurationLoads() {}
public void requestProtectedResourceRequiresAuthentication() throws Exception {
mvc.perform(get("/"))
.andExpect(redirectedUrl("http://localhost/login"));
}
@Test
public void loginSuccess() throws Exception {
mvc.perform(formLogin())
.andExpect(redirectedUrl("/"));
}
@Test
public void loginFailure() throws Exception {
mvc.perform(formLogin().password("invalid"))
.andExpect(redirectedUrl("/login?error"));
}
@Test
@WithMockUser
public void requestProtectedResourceWithUser() throws Exception {
mvc.perform(get("/"))
.andExpect(status().isOk());
}
@Test
@WithMockUser
public void composeMessageRequiresCsrfToken() throws Exception {
MockHttpServletRequestBuilder composeMessage =
post("/")
.param("summary", "New Message")
.param("text", "This is a new message");
mvc.perform(composeMessage)
.andExpect(status().isForbidden());
}
@Test
@WithMockUser
public void composeMessage() throws Exception {
MockHttpServletRequestBuilder composeMessage =
post("/")
.param("summary", "New Message")
.param("text", "This is a new message")
.with(csrf());
mvc.perform(composeMessage)
.andExpect(redirectedUrlPattern("/*"));
}
@Test
@WithMockUser
public void logoutRequiresCsrfToken() throws Exception {
mvc.perform(post("/logout"))
.andExpect(status().isForbidden());
}
@Test
@WithMockUser
public void logoutSuccess() throws Exception {
mvc.perform(logout())
.andExpect(redirectedUrl("/login?logout"))
.andExpect(unauthenticated());
}
}
+6 -6
View File
@@ -133,12 +133,6 @@
<version>4.0.2.RELEASE</version>
<scope>compile</scope>
</dependency>
<dependency>
<groupId>org.springframework</groupId>
<artifactId>spring-core</artifactId>
<version>4.0.2.RELEASE</version>
<scope>compile</scope>
</dependency>
<dependency>
<groupId>org.springframework</groupId>
<artifactId>spring-core</artifactId>
@@ -151,6 +145,12 @@
</exclusion>
</exclusions>
</dependency>
<dependency>
<groupId>org.springframework</groupId>
<artifactId>spring-core</artifactId>
<version>4.0.2.RELEASE</version>
<scope>compile</scope>
</dependency>
<dependency>
<groupId>org.springframework</groupId>
<artifactId>spring-instrument</artifactId>